fix: Home Assistant NET_RAW cap, container storage on LUKS, NET_BIND for all
- Home Assistant: add NET_RAW for DHCP discovery (fixes dhcp permission error)
- Nextcloud/BTCPay/Jellyfin/etc: add NET_BIND_SERVICE (was missing)
- Container storage: redirect graphroot to /var/lib/archipelago/containers/storage
(prevents root partition filling up — was 100% after 6 images on 29GB root)
Tested on .198: 10 containers running simultaneously:
Bitcoin Knots (syncing), LND (wallet ready), FileBrowser (healthy),
Grafana, Vaultwarden, SearXNG, Home Assistant, Electrumx,
Uptime Kuma, Jellyfin
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>